Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: us-bank (1 article)Clear

US Bank ties ransomware leak claim to a fourth-party vendor incident

US Bank said that data-theft claims made by the LockBit ransomware group stem from a fourth-party incident that happened outside its own environment, at a contractor working for one of its third-party vendors. The bank stated there is no evidence its own systems, networks, or data repositories were compromised, while LockBit set a deadline to leak the data unless paid. The "fourth-party" framing is the notable part: exposure reached the bank's customers through a vendor's vendor, two steps removed from its own controls. It follows earlier third-party incidents affecting US Bank customer data and underscores how far organizations' real attack surface extends beyond their direct suppliers.

Check
Map not just your direct vendors but their subcontractors, and require contractual security and breach-notification obligations that flow down to fourth parties handling your data.
Affected
Organizations whose data is handled by vendors' subcontractors; a breach at a fourth party can expose customer data even when your own and your direct vendor's systems are untouched.
Fix
Extend third-party risk management to fourth parties, inventory where data flows downstream, require flow-down security terms and prompt breach notification, and remember that paying extortion does not guarantee stolen data is deleted.